FlowplaneBook a pilot
Blog
GuideZero trust tunnel

European alternatives to Cloudflare Zero Trust and Zscaler: what to look at

Why EU firms look past US ZTNA providers (CLOUD Act, FISA 702, NIS2), what to check in a vendor, and a verified look at NetBird, GoodAccess, Enclave and more.

Zero trust network access (ZTNA) sits in the path of every login to your internal apps. The service sees who connected, from which device and IP address, to which system and when. Two of the best-known services, Cloudflare Zero Trust and Zscaler Private Access, come from American companies. This article explains why that matters to some buyers and which European options exist today. Prices and company details were checked on each vendor's own site on 29 September 2026.

Why European companies look for an EU alternative

The US CLOUD Act

The CLOUD Act was signed into US law in March 2018. Its core provision, 18 U.S.C. § 2713, requires a provider of electronic communication or remote computing services to disclose data in its "possession, custody, or control" whether that data is stored inside or outside the United States. For a provider under US jurisdiction, an EU data centre changes where the data is stored, and the disclosure obligation still applies to it.

That can put a provider between two legal systems. In their joint assessment of July 2019, the European Data Protection Board and the European Data Protection Supervisor concluded that providers subject to EU law cannot base a disclosure of personal data to the US on a CLOUD Act request alone, without an international agreement or another legal basis under the GDPR.

FISA section 702 and the Data Privacy Framework

Section 702 of the Foreign Intelligence Surveillance Act allows US intelligence agencies, with approval of the surveillance court, to target non-US persons located outside the United States, with service providers required to hand over the communications. In Schrems II (16 July 2020), the Court of Justice found that section 702 does not indicate limits on that power or guarantees for non-US persons, and it declared the EU-US Privacy Shield invalid.

The European Commission adopted a new adequacy decision, the EU-US Data Privacy Framework, on 10 July 2023. The General Court dismissed a challenge to it on 3 September 2025 (case T-553/23, Latombe v Commission). The applicant appealed on 31 October 2025, and the appeal (C-703/25 P) is pending before the Court of Justice. On the US side, the statutory authority for section 702 expired in June 2026 after Congress did not renew it, and had not been renewed at the time of writing, but the Brennan Center points out that surveillance under existing certifications can continue until March 2027.

The framework is valid law today. The Court of Justice struck down the two earlier US frameworks, Safe Harbour and Privacy Shield, and the current one is under appeal. Some companies accept that risk. Others prefer an access layer whose operator sits entirely under EU law.

NIS2 supplier risk

For companies in scope of NIS2, supplier choice is part of the security duty. Article 21(2)(d) of Directive (EU) 2022/2555 lists supply chain security, "including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers", among the minimum measures. Article 21(3) asks entities to take into account the vulnerabilities specific to each direct supplier and the quality of its cybersecurity practices. NIS2 does not ban non-EU providers. A ZTNA vendor is a direct supplier with a privileged position in your network, so where it is based and where it hosts your data belong in that assessment.

What to look at when you compare ZTNA vendors

European options, and some that are not

The table lists European ZTNA vendors plus two open-source options that are not European: NetFoundry, the company behind OpenZiti, is American, and Headscale is a community project. Prices are list prices from each vendor's pricing page on 29 September 2026, excluding VAT.

VendorCompany and countryHostingWhat it doesPublished list price
NetBirdNetBird GmbH, Berlin, GermanyManaged cloud or self-hosted; open sourceWireGuard mesh with SSO, MFA, access policies, private DNS; posture checks on BusinessFree up to 5 users; Team EUR 6 and Business EUR 12 per active user per month; Enterprise custom
GoodAccessGoodAccess s.r.o., Ústí nad Labem, CzechiaManaged cloud gateways; no self-hosted edition listedCloud gateways for private access, SSO, device posture check, DNS filteringEssential USD 7 (annual) or USD 9 (monthly), Premium USD 11 or USD 14, per user per month; 5-user minimum
EnclaveEnclave Networks Ltd, Newport, Wales, UKSaaS; no self-hosting option listedPolicy-driven overlay between devices and services, built for MSPsUSD 8 per enrolled system per month, USD 7.33 on annual billing
DefguardDefguard sp. z o.o., Szczecin, PolandSelf-hosted; open sourceWireGuard VPN with connection-level MFA, SSO, firewall rules, device postureOpen source free; Business free up to 10 users and 1 location, larger setups priced by calculator; Enterprise custom
OpenZiti / NetFoundryNetFoundry, Inc., Charlotte, North Carolina, USOpenZiti self-hosted; NetFoundry managed SaaS or self-hostedIdentity-based overlay with SDKs to embed zero trust in applicationsNot published
HeadscaleCommunity open-source project, no companySelf-hosted onlyOpen-source replacement for the Tailscale control serverFree (BSD-3-Clause)

NetBird

NetBird GmbH is registered in Berlin. Its client code is under the BSD-3-Clause licence, while the management, signal and relay components are under AGPLv3, so the whole stack can be self-hosted. The managed cloud includes geo-distributed relays, according to its documentation. That page does not name the country where the cloud control plane runs, so ask. NetBird is a network-level mesh with an agent on each device. It suits teams that want a VPN replacement with an open-source exit and per-user pricing in euros.

GoodAccess

GoodAccess s.r.o. is a Czech company. Its privacy terms say that by default it and its service provider process personal data only within the EU. It is delivered as a managed service with cloud gateways and connectors, integrates with Entra ID, Okta, Google Workspace and JumpCloud, and prices in US dollars. It fits SMEs that want a hosted service and have no appetite for running infrastructure.

Enclave

Enclave Networks Ltd is registered in Wales. The UK is outside the EU, but the Commission renewed its GDPR adequacy decision for the UK on 19 December 2025, valid until 27 December 2031. Enclave is SaaS, priced per enrolled system, and aimed at managed service providers with a multi-tenant partner portal.

Defguard

Defguard is a Polish company based in Szczecin. The product is self-hosted and open source, and it puts multi-factor authentication at the WireGuard connection itself. Its Business plan is free for up to 10 users and one location. It suits teams that want full control and can operate the servers.

OpenZiti and NetFoundry

OpenZiti is developed and open-sourced by NetFoundry, Inc. under the Apache 2.0 licence. NetFoundry is a US company in Charlotte, North Carolina, and offers a managed SaaS or a self-hosted deployment. A self-hosted OpenZiti network keeps data in your own infrastructure. A NetFoundry managed service puts a US company in the path.

Headscale

Headscale is an open-source, self-hosted implementation of the Tailscale control server. Its README says it is not associated with Tailscale Inc. and that it targets a single network for personal use or a small open-source organisation. For a company, it is an option for a technical team that accepts community support.

Non-European vendors with a similar product

Tailscale describes itself as a Canadian company, and its privacy policy says data is processed in Canada, Germany, the US and the UK. Twingate Inc. is a Delaware corporation. Pomerium, Inc. is a Delaware company based in Oregon; on its Zero plans the data plane is self-hosted. Firezone, Inc. is in San Francisco.

Where Cloudflare Zero Trust and Zscaler still stand out

Cloudflare's Zero Trust plans start with a free tier for up to 50 users with up to 24 hours of log retention, followed by pay-as-you-go at USD 7 per user per month with up to 30 days of logs, and contract pricing above that. None of the managed European services above offers a free tier of that size. Cloudflare also sells a Data Localization Suite as an Enterprise-only paid add-on. Its Customer Metadata Boundary can keep logs in the EU or the US. Cloudflare, Inc. is headquartered in San Francisco.

Zscaler, based in San Jose, California, sells private access as part of a larger platform that includes internet access security, data security and digital experience monitoring. In March 2026 it described a dedicated US and European control plane, regional or on-premises log storage, and customer-hosted Private Service Edges. Its pricing page lists bundles but no prices.

Both are large platforms with their own global networks. If you need a full SASE stack, or a free start for a team under 50 users, they belong on the shortlist. Their regional options control where data is stored, while the parent company remains under US law.

AI agents are becoming part of access control

Staff can now connect AI assistants to internal systems through the Model Context Protocol (MCP). The MCP authorization specification builds on OAuth 2.1 for servers reached over HTTP, which moves agent access into the same identity questions as human access.

Vendors are responding in different ways. Cloudflare's MCP server portals put several MCP servers behind one endpoint under Access policies, though the documentation notes that independent MFA, purpose justification and temporary authentication are not enforced for servers authorised through a portal. NetBird's repository lists an Agent Network in beta for identity-aware access to LLM APIs. NetFoundry markets AI access governance.

Some of these features are still in beta. When you evaluate a vendor, ask:

A short note on Flowplane

Flowplane is building a European zero trust gateway for people and AI agents, run by a Belgian company. It is at the concept stage today and will be announced here when there is something to test.

Sources